Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48827

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected. Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4. We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.

A flaw was found in Apache MINA SSHD bundle sshd-git. This path traversal vulnerability allows authenticated users to access Git repositories located outside the intended server root directory. The lack of proper path validation during Git operations, such as git-upload-pack and git-receive-pack, enables an attacker to bypass security restrictions. This could lead to unauthorized information disclosure from other repositories on the system.

Меры по смягчению последствий

To mitigate this issue, ensure the Git server environment is configured with strict access controls and isolation. Restrict operating system user accounts used for SSH Git access to their intended repository roots, potentially using chroot jails or similar mechanisms. Implement additional authorization layers to govern access to Git repositories and operations, preventing authenticated users from traversing outside the designated server root directory. Review and harden file system permissions to limit access to sensitive directories.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8sshd-gitFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packsshd-gitFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2483783org.apache.sshd/sshd-git: Apache MINA SSHD: Path Traversal Vulnerability Allows Access to Unauthorized Git Repositories

EPSS

Процентиль: 42%
0.00527
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
2 месяца назад

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected. Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4. We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.

CVSS3: 7.1
nvd
2 месяца назад

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH access to git repositories outside the configured git server root directory. Applications are affected if they use org.apache.sshd:sshd-git. Applications not using sshd-git are not affected. Users are advised to upgrade affected applications to Apche MINA SSHD 2.18.0, which fixes the issue. The issue also is present in the pre-release milestones 3.0.0-M1 to 3.0.0-M3 for a new upcoming new major version 3.0.0. Again, applications are affected only if they use sshd-git. Upgrade affected applications to 3.0.0-M4. We would like to point out that a professional git server should not rely solely on file system layout and permissions, but should implement additional security controls to govern access to git repositories and operations allowed on particular git repositories.

CVSS3: 7.1
debian
2 месяца назад

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack ...

CVSS3: 7.1
github
2 месяца назад

Apache MINA SSHD bundle sshd-git has a path traversal vulnerability

suse-cvrf
около 2 месяцев назад

Security update for apache-sshd, jpgpj

EPSS

Процентиль: 42%
0.00527
Низкий

6.5 Medium

CVSS3